Back to skill

Security audit

Dataify Instagram Profiles

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Dataify wrapper for submitting Instagram profile collection tasks, with token and network use that fit its stated purpose.

Before installing, understand that this skill can use a locally saved DATAIFY_API_TOKEN and send Instagram usernames or profile URLs to Dataify to create collection jobs. Only use it when you intend to submit those jobs, and avoid saving the token locally unless that fits your security practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs the agent to read a local environment variable and make outbound network requests, but the skill metadata does not declare those capabilities. Undeclared access to env and network reduces transparency and weakens policy enforcement, which can lead to unintended token use or external data transmission without clear user understanding.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description includes very broad trigger phrases covering generic scraping, profile collection, troubleshooting, token configuration, and multilingual variants. This can cause the agent to invoke the skill for loosely related requests, increasing the chance of unintended external data collection actions or unnecessary handling of API credentials when a user only wanted general information or discussion.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.